This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Error code 1603 when upgrading from SEC 5.0 to 5.1

Hi,

I'm currently trying to upgrade an existing SEC 5.0 installation to 5.1, but it's failing with an error 1603 message "Unable to install Management Server - The MSI terminated unexpectedly".  I've followed the steps on http://www.sophos.com/en-us/support/knowledgebase/114627.aspx and also had a look through another post here ( /search?q= 22257 ) but haven't yet found a definite solution.

The Sophos_bootstrapper... log file has the following at the end:

31/05/2012 12:57:30, INFO : Ended installing Database32.msi
31/05/2012 12:57:32, INFO : Installation of Database succeeded
31/05/2012 12:57:32, INFO : Verifying files in folder
31/05/2012 12:57:34, INFO : Target folder verification completed successfully
31/05/2012 12:57:34, INFO : About to install Server32.msi
31/05/2012 13:06:18, INFO : Processing INSTALLMESSAGE_ERROR or INSTALLMESSAGE_FATALEXIT message from MSI
31/05/2012 13:06:18, INFO : Deactivate state: Installing
31/05/2012 13:06:18, INFO : Activate state: Failing
31/05/2012 13:07:03, INFO : Installation of Server32.msi failed with error code: 1603
31/05/2012 13:07:03, INFO : Ended installing Server32.msi
31/05/2012 13:07:05, INFO : Installation failed with error code: 1603
31/05/2012 13:07:05, INFO : Deactivate state: Failing
31/05/2012 13:07:05, INFO : Activate state: Failed
31/05/2012 13:07:05, INFO : Entered Installation failed page.
31/05/2012 13:07:27, INFO : Opening logs folder: C:\Documents and Settings\All Users\Application Data\Sophos\Management Installer
31/05/2012 13:07:27, ERROR : Could not open temp folder. ShellExecute() returned error: 33 - The process cannot access the file because another process has locked a portion of the file.

which seems odd because nothing else is running on the server (logged in as domain administrator for the installation, and log files are being created in the temp folder).  Additionally, the Sophos_Server32msi... log file contains the following:

MSI (s) (38:9C) [13:05:51:981]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI8E.tmp, Entrypoint: InitializeDatabaseAndImportCertificates
SFXCA: Extracting custom action to temporary directory: C:\WINDOWS\Installer\MSI8E.tmp-SFXCA: Binding to CLR version v2.0.50727
Calling custom action EncryptionCustomActions!EncryptionCustomActions.CustomAction.InitializeDatabaseAndImportCertificates
InitializeDatabaseAndImportCertificates
About to call: Initialize
Succeeded: Initialize
Calling API function: CreateMiscClassInstance().
Completed API function: CreateMiscClassInstance().
About to call: Initialize
Succeeded: Initialize
About to call: InitializeDatabaseEx
Succeeded: InitializeDatabaseEx
About to call: AuthenticateOfficer
MSI (s) (38!64) [13:06:18:308]: Product: Sophos Management Server -- 1: You do not have sufficient rights to perform the action. Access is denied. 

Exception thrown by custom action:
System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> EncryptionCustomActions.SgnApiException: You do not have sufficient rights to perform the action. Access is denied.
   at EncryptionCustomActions.CustomAction.CallFunction(String functionName, Func`1 function, Session session, Base baseObject)
   at EncryptionCustomActions.CustomAction.InitializeDatabaseAndImportCertificates(Session session)
   --- End of inner exception stack trace ---
   at System.RuntimeMethodHandle._InvokeMethodFast(Object target, Object arguments, SignatureStruct& sig, MethodAttributes methodAttributes, RuntimeTypeHandle typeOwner)
   at System.RuntimeMethodHandle.InvokeMethodFast(Object target, Object arguments, Signature sig, MethodAttributes methodAttributes, RuntimeTypeHandle typeOwner)
   at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object parameters, CultureInfo culture, Boolean skipVisibilityChecks)
   at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object parameters, CultureInfo culture)
   at Microsoft.Deployment.WindowsInstaller.CustomActionProxy.InvokeCustomAction(Int32 sessionHandle, String entryPoint, IntPtr remotingDelegatePtr)
MSI (s) (38:00) [13:06:20:418]: User policy value 'DisableRollback' is 0
MSI (s) (38:00) [13:06:20:418]: Machine policy value 'DisableRollback' is 0
Action ended 13:06:20: InstallFinalize. Return value 3.

which looks like there's a problem with importing the Safeguard certificate(???).  I don't have Safeguard Enterprise, just the standard version, but I do have a message in Enterprise Console saying my licence has been updated to the Data Protection Suite and have verified that the certificate passwords are entered correctly.

I suppose the obvious thing to try is to just forget about the encryption, but I'd really rather have it managed from the same console if possible - ideally importing the already encrypted machines.

Does anyone have any idea if I'm doing something wrong here?  Previous upgrades of both Safeguard Policy Editor and SEC have always gone without any problems until now.

Thanks in advance for any advice!

:25389


This thread was automatically locked due to age.
Parents
  • This post has been edited by moderator / Sophos Technical Support:-

    IMPORTANT

    Jak is asking if you had the Policy Editor installed.  He is NOT  advising that you uninstall the Policy Editor.  If you experience this problem, please do not uninstall the Policy Editor but contact Sophos Technical Support for further assistance. 


    jak wrote:

    HI,

    Do you have the Policy Editor installed on the same machine as the SEC Server?



    Yes, I do have Policy Editor installed on the same machine as SEC.  I never noticed anything in the upgrade guide regarding this (yes, I did actually read it :smileywink: ), but I'd be willing to try an upgrade after uninstalling it (thankfully the server is a VM, so when things go wrong, this is where snapshots come in handy).  I did have a look through the bootstrap log and found the following lines:

    31/05/2012 12:55:27, INFO : Running System Property Check: Sophos Safeguard Policy Editor installed on this computer...
    31/05/2012 12:55:27, INFO : Product is not installed on local system. Upgrade code: {D4667A84-D644-40DA-8344-F1D9839C1BB4}
    31/05/2012 12:55:27, INFO : System Property Check: Sophos Safeguard Policy Editor installed on this computer - PASSED

    I'll wait until later this afternoon when things are a bit quieter and give it a try after removing Policy Editor.

    Thanks for the advice!

    :25439
Reply
  • This post has been edited by moderator / Sophos Technical Support:-

    IMPORTANT

    Jak is asking if you had the Policy Editor installed.  He is NOT  advising that you uninstall the Policy Editor.  If you experience this problem, please do not uninstall the Policy Editor but contact Sophos Technical Support for further assistance. 


    jak wrote:

    HI,

    Do you have the Policy Editor installed on the same machine as the SEC Server?



    Yes, I do have Policy Editor installed on the same machine as SEC.  I never noticed anything in the upgrade guide regarding this (yes, I did actually read it :smileywink: ), but I'd be willing to try an upgrade after uninstalling it (thankfully the server is a VM, so when things go wrong, this is where snapshots come in handy).  I did have a look through the bootstrap log and found the following lines:

    31/05/2012 12:55:27, INFO : Running System Property Check: Sophos Safeguard Policy Editor installed on this computer...
    31/05/2012 12:55:27, INFO : Product is not installed on local system. Upgrade code: {D4667A84-D644-40DA-8344-F1D9839C1BB4}
    31/05/2012 12:55:27, INFO : System Property Check: Sophos Safeguard Policy Editor installed on this computer - PASSED

    I'll wait until later this afternoon when things are a bit quieter and give it a try after removing Policy Editor.

    Thanks for the advice!

    :25439
Children
No Data